{"apiVersion":"1.0","identifier":"CVE-2026-72483","description":"In the Linux kernel, the following vulnerability has been resolved: usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() The `max3421_hub_control()` function handles USB hub class requests to the virtual root hub. In the `default` branches of both the `ClearPortFeature` and `SetPortFeature` switch statements, it modifies `max3421_hcd->port_status` by left shifting 1 by the request-s `value` parameter. However, it does not validate whether this shift will exceed the width of `port_status`. So if a malicious userspace task with access to the root hub via /dev/bus/usb/.../001 issues a USBDEVFS_CONTROL ioctl with `wValue` greater than or equal to 32, the left shift operation invokes shift-out-of-bounds undefined behavior. This results in arbitrary bit corruption of `port_status`, including the normally-immutable change bits, which can bypass internal state checks and confuse the hub status. Fix this by rejecting requests whose `value` exceeds the shift width before performing the shift. This issue was found using a KLEE-based symbolic execution tool for kernel drivers that I-m currently developing.","publishedAt":"2026-08-15T06:22:22","lastModifiedAt":"2026-08-17T06:19:16","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-72483","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","epssProbability":0.00181,"riskScore":0.79,"affectedProduct":"Linux kernel","affectedVersions":"unknown","vulnerabilityType":"Kernel","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-72483","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-72483","en":"https://www.redsauce.net/en/cves/CVE-2026-72483","fr":"https://www.redsauce.net/fr/cves/CVE-2026-72483","pt":"https://www.redsauce.net/pt/cves/CVE-2026-72483","de":"https://www.redsauce.net/de/cves/CVE-2026-72483","sk":"https://www.redsauce.net/sk/cves/CVE-2026-72483","el":"https://www.redsauce.net/el/cves/CVE-2026-72483"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-72483"}}